Live data from Hacker News

Dropgangs, or the future of darknet markets

opaque.link

171–180 of 195 posts

Re: Dropgangs, or the future of darknet markets

#171

How do you defend against the eye in the sky, video surveillance or location tracking ? There seems to be conflicting objectives. When hiding an object you don't want too many people around to see where you hide it. Yet if you record only two person going to exactly the same non standard spot it's pretty much a red flag, then you follow the person in the recording to identify them. Most buildings are probably not val…

Yeah, it's a great story, but machine vision + machine learning + surveillance could pull the rug out from the dropgangs market in a second. But really, other than this fatal flaw, it's a great narrative of the internet spilling into and interfacing with analog markets

> Yeah, it's a great story, but machine vision + machine learning + surveillance could pull the rug out from the dropgangs market in a second.

Even when the dead drop could be as subtle as attaching something under a public bench or dropping something in a trash can?

Re: Dropgangs, or the future of darknet markets

#172

Earlier quoted context omitted.

I think if “he left surveilled areas for no registered reason” is something that law enforcement observes and considers evidence of criminal activity, we’ll have well and truly lost any semblance of being a free society.

"Parallel Construction" ... yep, sad times https://en.wikipedia.org/wiki/Parallel_construction

I don't see how parallel construction applies here.

Re: Dropgangs, or the future of darknet markets

#173

Earlier quoted context omitted.

Criminal networks do benefit from a bread-and-butter businesses like drug distribution. These innovations likely wouldn't be taking place at all if altering one's own consciousness with substances hadn't been criminalized - when the law is made to be at odds with society, society adapts to being at odds with the law. But unlike say murder, "identity theft" isn't some serious crime - it's in the same basket as "war on…

How could identity theft need fixed?

(Re)design systems so that they rightfully treat eg SSN as a mere database key rather than negligently imagining it some kind of shared secret. How this gets applied and the implications differ for each trust relationship.

For example, if you have a bank account at a brick-and-mortar bank (and haven't setup online access), anybody can obtain online access to that account by going to the bank's website and entering your name, social security number, and maybe the recent account balance. This is in fact the exact process a bank rep does when you open a new account if they setup that access for you, or sometimes they even tell you to go home and do this yourself! Similarly, if you forget your online banking password, you can reset it entirely online with access to your email account, making your email account more trusted than the bank account!

In actuality, your being in the bank in person is the primary trust relationship, and that needs to be leveraged for the above scenarios. So online access should only ever be setup in a branch, and perhaps password resets should even require going down there as well.

(Obviously this is just an example and does not also apply to online-only banks. As I said, the key is to stop treating quasi-public information as a shared secret)

Re: Dropgangs, or the future of darknet markets

#174

Earlier quoted context omitted.

"Identity Theft" is a marketing spin on "broken identification". An identity is unique by definition and can't be stolen. But if you use an inadequate identification technique, like my birthday that's on my facebook and everywhere else in combination with my social security number that I have to give out to just about everybody, anyone can aquire those two pieces of information and impersonate me. The ways to fix it…

This is something that has always frustrated me when reading about identity theft in the US. It's a problem that can only be fixed through legislation, yet I haven't heard of any even remotely successful attempts at establishing an official form of identification. Smart cards would be ideal, but even a simple national ID card with a picture would prevent the vast majority of identity theft. I've done some research ar…

Strengthening the technicals of verifying identity won't solve it. In fact, doing so will serve as justification to double down on the crutch rather than fixing the root problem of incorrect security assertions, causing the individual victims even more problems.

The real legislation that is needed is to statutorily shore up the banks' liability for the damage their negligence causes. A person that has to deal with fall out from a bank being defrauded (eg repudiating that bank's and surveillance bureaus' libel) should receive a decent hourly wage in liquidated damages.

Re: Dropgangs, or the future of darknet markets

#179
post #121

Dead drop based drug distribution doesn’t scale to retail levels. It is used in Moscow and I know of people who will order from a dealer, then search the surrounding area and clear out all the drops they find. It works for them, although one questions the sanity of stealing from Russian drug dealers. For more practical guides on how people who sell drugs avoid the negative repercussions: • AlpraKing’s business guide…

Yeah, dead drops obviously work for experts. But as cool as TFA may sound, I can't see it working out well for low-level distributors and customers.

And yes, great links!

Re: Dropgangs, or the future of darknet markets

#180

Earlier quoted context omitted.

This is something that has always frustrated me when reading about identity theft in the US. It's a problem that can only be fixed through legislation, yet I haven't heard of any even remotely successful attempts at establishing an official form of identification. Smart cards would be ideal, but even a simple national ID card with a picture would prevent the vast majority of identity theft. I've done some research ar…

Strengthening the technicals of verifying identity won't solve it. In fact, doing so will serve as justification to double down on the crutch rather than fixing the root problem of incorrect security assertions, causing the individual victims even more problems. The real legislation that is needed is to statutorily shore up the banks' liability for the damage their negligence causes. A person that has to deal with fa…

That's a fair point - more accountability is definitely needed.

But while I agree that tech alone wouldn't fix much, using a single number (with no biometrics whatsoever) for identification is just asking for trouble. Even my bus pass has my picture on it!

Post reply on HN